296,172
Total vulnerabilities in the database
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
Software | From | Fixed in |
---|---|---|
openssl / openssl | 1.0.2b | 1.0.2n.x |
openssl / openssl | 1.1.0 | 1.1.0g.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 7.0 | 7.0.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
debian / debian_linux | 9.0 | 9.0.x |
canonical / ubuntu_linux | 17.10 | 17.10.x |